Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.
"https://github.com/pypa/advisory-database/blob/main/vulns/radicale/PYSEC-2017-102.yaml"